Clubs & Gaming · Cyber security
NSW clubs data breach: what we know, who's affected, and what to do
First-hand assessment of the Outabox sign-in system breach, written for club managers and boards on the day it broke.
Published
Incident summary
It was reported across major news outlets that a significant breach of club member information had occurred. The data was alleged to include facial recognition records, driver licence details, signatures and addresses.
The source appeared to be the Outabox sign-in system, with claims that overseas-based software developers who had not been paid for over a year released the information.
Gaming information also appeared to have been exposed via the IGT API. Because each API key is limited on a club-by-club basis, that constrained how much data any single key could reach.
Who was affected
At the time, this affected only clubs running the Outabox sign-in system — predominantly a number of major clubs in the Sydney region.
No clubs in Northern NSW appeared to be affected, so no immediate action was required for our client base. We said so at the time rather than using the incident to manufacture urgency, and we would say the same again.
The actual lesson: third-party access
Strip away the specifics and this breach points at the single largest cyber risk in a club environment: third parties with access to member data.
Marketing platforms. Outsourced loyalty schemes. Sign-in and ID-scanning systems. Gaming interfaces. Analytics providers. Each is a legitimate business tool, each holds or reaches member data, and each represents an access path your club does not directly control.
The uncomfortable part is that your obligation to your members does not transfer with the data. If a supplier's developer in another country exposes your members' driver licences, it is your members and your board who deal with it.
What a club should actually do
- List every third party that touches member data, including the ones procured by marketing rather than by IT. Most clubs are surprised by the length of this list
- Review what each one can actually reach, rather than what it was set up to do
- Remove access that is no longer needed — former suppliers, completed projects, staff who have moved on
- Scope API keys per club and per function, which is exactly what limited the gaming exposure in this incident
- Ask each supplier where their development is done and how their own access is controlled. It is a fair question and the answers are informative
- Review it on a cycle, because access accumulates
Third-party access review is part of our regular NEVO Secure checks. It is unglamorous work and it is the control that would have mattered most here.
The other standing threat
Alongside third-party access, socially engineered attacks remain the key threat actively facing clubs — a convincing message to the person who pays invoices or resets passwords. See anti-phishing and awareness training.
It is also worth communicating any change in circumstances — a supplier relationship ending, a staff departure — to third-party providers promptly. Delay there is what turns a routine change into an exposure.
More insights
Book a Technology Review.
One to two hours onsite, across support, cyber posture, backup and recovery, infrastructure, Microsoft 365 and where the organisation is heading. You receive a written findings report within five days — prioritised risks, quick wins and gaps, in writing.
$1,500 including GST. Credited in full against your engagement if you proceed.
The report is yours to keep regardless of what you decide to do next.
The 90-day guarantee. Give us 90 days. If you're not satisfied with our service in that time, cancel and we'll refund our fees. You keep the audit, the report and every improvement we've made. Third-party hardware, licences and subscriptions purchased on your behalf are excluded. Full terms
